# Single Sign On with Active Directory

**URL:** <https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 28, 2016, 10:34pm UTC](https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421 "2016-01-28T22:34:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [January 28, 2016, 10:34pm UTC](https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421/1 "2016-01-28T22:34:31Z")

</div>

Is there a way I can configure single sign on or pass-through authentication so that kibana does not prompt all of my users for their credentials but pulls them in?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 28, 2016, 11:34pm UTC](https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421/2 "2016-01-28T23:34:09Z")

</div>

Auth with KB is coming with 4.4, which will land very soon.

Not sure about SSO though.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 29, 2016, 11:57am UTC](https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421/3 "2016-01-29T11:57:53Z")

</div>

Active Directory SSO is typically done with kerberos via SPNEGO. Shield does not support this out of the box but a [custom realm](https://www.elastic.co/guide/en/shield/current/custom-realms.html) could be written to support this method of authentication.

There is a [community plugin](https://github.com/codecentric/elasticsearch-shield-kerberos-realm) that has been implemented that may provide this support, but I have not used it before.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/single-sign-on-with-active-directory/40421/4 "2017-07-06T13:47:07Z")

</div>


